Skip to main content

Kur1sulab/blackbox

SkillsMP는 Kur1sulab/blackbox에서 116개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
116
GitHub 스타
3
GitHub 포크
1

AI 어시스턴트로 설치

이 프롬프트를 복사해 사용 중인 AI 어시스턴트에 입력하세요.

이 저장소의 Agent Skills 설치를 도와주세요: https://github.com/Kur1sulab/blackbox
먼저 출처, SKILL.md 및 관련 파일을 확인하고 설치 가능한 Skill 목록을 보여주세요. 제가 선택하면 해당 Skill의 전체 디렉터리를 현재 프로젝트에 설치하고 필요한 파일이 모두 있는지 확인해 주세요.

이 저장소의 skills

수집된 skill 116개 중 40개를 표시합니다.

직업 분류
미분류
설명

Use when 黑盒打 Django/DRF 后端站(DEBUG取证/越权矩阵/上传/JWT爆破).

원문 언어: 중국어

업데이트
직업 분류
미분류
설명

构建/运维 Go+Docker Kali+Ollama 多模型渗透工作台。

원문 언어: 중국어

업데이트
직업 분류
미분류
설명

LAN device enum and router recon from Windows.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

构建 AI 驱动自动化渗透 Agent 框架。覆盖架构/双模式/工具注册/Docker Kali/Web 仪表盘。

원문 언어: 중국어

업데이트
직업 분류
정보 보안 분석가
설명

401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format string, or OOB write) and need to convert it into code execution by targeting GOT, hooks, _IO_FILE vtable, exit_funcs, TLS_dtor_list,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8 sandbox bypass to achieve renderer RCE and sandbox escape in Chrome/Chromium.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and browser-based access to authenticated APIs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in decentralized finance protocols.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for origin checks, interact with internal services from browser context, or when SSRF is not possible server-side but the target has client-side fetch/XHR to…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that constructs SMTP messages with user-controlled fields. Covers CRLF injection in headers, SPF/DKIM/DMARC bypass, and phishing…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion, upload flows, preview pipelines, archive extraction, or storage and sharing boundaries.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook overwrites, and canary/libc/PIE leaks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, or choosing the right next category skill before any deep topic skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary framing, HPACK compression, h2c upgrade smuggling, pseudo-header injection, stream multiplexing abuse, or H2→H1 downgrade translation flaws.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on how attacker-controlled input is consumed.

원문 언어: 영어

업데이트
수집된 skill 116개 중 40개를 표시합니다.